CompTIA Security SY0-601 Exam Study Guide with

Questions & answers Sep 5, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CompTIA Security+ SY0-601 Exam Study Guide with Complete Solutions 2024/2025 What type of certificate does a CA have? - Correct Answer Root Certificate; used to sign keys If I am going to use a CA internally, what type of CA should I use? - Correct Answer Private CA If I want to carry out a B2B activity with third-party companies or sell products on the web, what type of certificate should I use? - Correct Answer Public CA Why would I make my CA offline when not in use? - Correct Answer Military, Security, or Banking Organizations; preventing data from being compromised.Who signs X.509 certificates? - Correct Answer Central Authorities (CA) Who builds the CA or intermediate authorities? - Correct Answer Architect What can I use to prevent my CA from being compromised and fraudulent certificates being issued? - Correct Answer Certificate Pinning If two entities what to set up a cross-certification, what must they set up first? - Correct Answer Root CAs using a bridge trust model What type of trust model does PGP use? - Correct Answer Web of Trust How can I tell if my certificate is valid? - Correct Answer Certificate Revocation List (CRL) If the CRL is going slow, what should I implement? - Correct Answer Online Certification Status Protocol

(OCSP)

Explain certificate stapling/OCSP stapling - Correct Answer Web servers use an OCSP for faster authentication bypassing the CRL 1 / 3

What is the process of obtaining a new certificate - Correct Answer Certificate Signing Request (CSR) What is the purpose of key escrow? - Correct Answer Holds an provides access to 3rd party keys provided the need.What is the purpose of Hardware Security Model (HSM) - Correct Answer Used by key escrow to store and manage keys What is the purpose of DRA and what does it require in order to complete its role effectively? - Correct Answer When a users private key becomes corrupt, the DRA recovers data by obtaining a copy of the private key from the key escrow.How can I identify each certificate - Correct Answer Object Identifier (OID) or the serial number What format is a private certificate? - Correct Answer P12 What file extension is a private certificate? - Correct Answer .pfx extension What format is a public certificate? - Correct Answer P7B What file extension is a public certificate? - Correct Answer .cer extension What format is a PEM certificate? - Correct Answer Base64 What type of certificate can be used on multiple servers in the same domain - Correct Answer Wildcard (denoted by a *) What type of certificate can be used on multiple domains? - Correct Answer Subject Alternative Name

(SAN) 2 / 3

What should I do with my software to verify that it is original and not a fake copy (verify integrity)? - Correct Answer Code Signing What is the purpose of extended validation of an X.509 certificate? - Correct Answer Provides Financial institutions with a higher level of trust.What is the purpose of DH? - Correct Answer Creates a secure tunnel; during a VPN connection (on port 500), used during IKE What two things does digitally signing an email provide? - Correct Answer Integrity and Non-repudiation What asymmetric encryption algorithm should I use to encrypt data on a smartphone? - Correct Answer ECC (Elliptic Curve Cryptography) What shall I use to encrypt a military mobile phone? - Correct Answer AES-256 Name two key stretching algorithms - Correct Answer Bcrypt & PBKDF2 What is the purpose of key stretching? - Correct Answer To make weak passwords less volatile to brute- force attacks What happens to Cipher Block Chaining (CBC) if I do not have all the blocks? - Correct Answer No decryption is possible If I want to ensure integrity of data, what shall I use? - Correct Answer MD5 & SHA-1 What type of man-in-the-middle (MITM) attack is SSL 3.0 (CBC) vulnerable to? - Correct Answer POODLE What is the usage of Diffie Hellman Ephemeral (DHE) and Elliptic Curve Diffie Hellman Ephemeral (ECDHE) - Correct Answer one time keys

  • / 3

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Questions & answers
Added: Sep 5, 2025
Description:

CompTIA Security+ SY0-601 Exam Study Guide with Complete Solutions What type of certificate does a CA have? - Correct Answer Root Certificate; used to sign keys If I am going to use a CA internally...

Get this document $30.00